Malware

MSIL/Kryptik.YIS removal instruction

Malware Removal

The MSIL/Kryptik.YIS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.YIS virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.YIS?


File Info:

crc32: EF40865E
md5: 34bbaf88d62ba189eb03bd77d951bd6d
name: aa.exe
sha1: d4e0c30a7bada784812775152353a1978280a98d
sha256: b6e903d258e6a91764bafc30f90bca8ad0753b8359278bed0ae21cdef654724c
sha512: 0417fcae5d41fe1b0c44a6cb435b96159ba3b69aa4681fdcd2940d7ba9f972b41a4725137e52d8de27073e11dbb5305b767748bef810dfe8858a2942f518c7a0
ssdeep: 3072:o1JZ3l42+dZZJyekZf0h8zrqFEYFl0GMY:o101Jv2fq
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: Lime_build.exe
FileVersion: 1.0.0.0
ProductName: VideoLAN
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: Lime_build.exe

MSIL/Kryptik.YIS also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44179089
FireEyeGeneric.mg.34bbaf88d62ba189
McAfeeRDN/Generic PWS.y
SangforMalware
K7AntiVirusTrojan ( 00571c5e1 )
BitDefenderTrojan.GenericKD.44179089
K7GWTrojan ( 00571c5e1 )
Cybereasonmalicious.a7bada
CyrenW32/MSIL_Kryptik.BLX.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Remcos.gen
AlibabaBackdoor:Win32/Remcos.b97506d4
Ad-AwareTrojan.GenericKD.44179089
ComodoMalware@#y3ljth86s5k9
DrWebTrojan.PWS.Stealer.29471
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S
JiangminBackdoor.MSIL.duwp
AviraHEUR/AGEN.1138209
MicrosoftTrojanSpy:MSIL/Stelega.RIA!MTB
ZoneAlarmHEUR:Backdoor.MSIL.Remcos.gen
GDataTrojan.GenericKD.44179089
AhnLab-V3Trojan/Win32.Wacatac.C4212046
BitDefenderThetaGen:NN.ZemsilF.34590.Bm0@aa4NiCf
ALYacTrojan.GenericKD.44179089
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.YIS
TencentMsil.Backdoor.Remcos.Lknz
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetPossibleThreat
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Backdoor.23a

How to remove MSIL/Kryptik.YIS?

MSIL/Kryptik.YIS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment